package com.lyc.ojcodesandbox.core;

import cn.hutool.core.date.StopWatch;
import cn.hutool.core.io.FileUtil;
import cn.hutool.core.io.resource.ResourceUtil;
import cn.hutool.core.util.StrUtil;
import cn.hutool.dfa.WordTree;
import com.lyc.ojcodesandbox.core.CodeSandbox;
import com.lyc.ojcodesandbox.model.ExecuteCodeRequest;
import com.lyc.ojcodesandbox.model.ExecuteCodeResponse;
import com.lyc.ojcodesandbox.model.ExecuteMessage;
import com.lyc.ojcodesandbox.model.JudgeInfo;
import com.lyc.ojcodesandbox.utils.ProcessUtils;

import java.io.File;
import java.io.IOException;
import java.nio.charset.StandardCharsets;
import java.util.ArrayList;
import java.util.Arrays;
import java.util.List;
import java.util.UUID;

public class JavaNativeCodeSandboxOld implements CodeSandbox {
    
    private static final String GLOBAL_CODE_DIR_NAME = "tmpCode";
    
    private static final String GLOBAL_JAVA_CLASS_NAME = "Main.java";
    
    private static final long TIME_OUT = 5000L;
    
    private static final String SECURITY_MANAGER_PATH = "D:\\Acode\\oj\\oj-code-sandbox\\src\\main\\resources\\security";
    
    private static final String SECURITY_MANAGER_CLASS_NAME = "MySecurityManager";
    
    private static final List<String> blackList = Arrays.asList("Files","exec");
    
    private static final WordTree WORD_TREE;
    
    static {
        //初始化字典树，只需进行一次，添加黑名单的字符串
        WORD_TREE = new WordTree();
        WORD_TREE.addWords(blackList);
    }

    public static void main(String[] args) {
        JavaNativeCodeSandboxOld javaNativeCodeSandbox = new JavaNativeCodeSandboxOld();
        ExecuteCodeRequest executeCodeRequest = new ExecuteCodeRequest();
        executeCodeRequest.setInputList(Arrays.asList("1 2", "3 4"));
        //1、 获取用户代码，通过ResourceUtil.readStr可以直接读取里面的字符串，这里做测试，代码放在resource路径下的testCode里面
//        String code = ResourceUtil.readStr("testCode/simpleComputeArgs/Main.java", StandardCharsets.UTF_8);
        //2、 测试交互式代码
//        String code = ResourceUtil.readStr("testCode/simpleCompute/Main.java", StandardCharsets.UTF_8);
        //3、 测试睡眠代码
//        String code = ResourceUtil.readStr("testCode/unsafeCode/SleepError.java", StandardCharsets.UTF_8);
        //4、 测试占用内存代码
//        String code = ResourceUtil.readStr("testCode/unsafeCode/MemoryError.java", StandardCharsets.UTF_8);
        //5、 测试文件泄露代码
//        String code = ResourceUtil.readStr("testCode/unsafeCode/ReadFileError.java", StandardCharsets.UTF_8);        
        //6、 测试植入文件代码
//        String code = ResourceUtil.readStr("testCode/unsafeCode/WriteFileError.java", StandardCharsets.UTF_8);
        //6、测试运行程序代码
        String code = ResourceUtil.readStr("testCode/unsafeCode/RunFileError.java", StandardCharsets.UTF_8);
        
        executeCodeRequest.setCode(code);
        executeCodeRequest.setLanguage("java");
        ExecuteCodeResponse executeCodeResponse = javaNativeCodeSandbox.executeCode(executeCodeRequest);
        System.out.println(executeCodeResponse);

    }
    
    
    @Override
    public ExecuteCodeResponse executeCode(ExecuteCodeRequest executeCodeRequest) {
//        System.setSecurityManager(new DenySecurityManager());
        
        List<String> inputList = executeCodeRequest.getInputList();
        String code = executeCodeRequest.getCode();
        String language = executeCodeRequest.getLanguage();
        
        //校验黑名单代码，防止代码中有写文件的程序，植入木马
//        FoundWord foundWord = WORD_TREE.matchWord(code);
//        if(foundWord != null) {
//            System.out.println("包含敏感词：" + foundWord.getFoundWord());
//            return null;
//        }

        // todo 创建目录不应该在执行代码类中存放，全局类的东西不应该反复执行，会浪费时间
        // 1 把用户的代码保存为文件
        //获取当前用户的工作目录，项目的根目录
        String userDir = System.getProperty("user.dir");
        String globalCodePathName = userDir + File.separator + GLOBAL_CODE_DIR_NAME;
        //判断全局代码目录是否存在,没有则新建
        if(!FileUtil.exist(globalCodePathName)){
            FileUtil.mkdir(globalCodePathName);
        }
        //把用户的代码隔离存放
        //用户代码的父目录
        String userCodeParentPath = globalCodePathName + File.separator + UUID.randomUUID();
        //用户代码的目录
        String userCodePath = userCodeParentPath + File.separator + GLOBAL_JAVA_CLASS_NAME;
        //将代码写入到文件当中
        File userCodeFile = FileUtil.writeString(code, userCodePath, StandardCharsets.UTF_8);
        
        // 2 编译代码，得到class文件,执行命令行，需要用到Runtime类，Runtime.getRuntime().exec()
        String compileCmd = String.format("javac -encoding utf-8 %s", userCodeFile.getAbsolutePath());
        try {
            Process compileProcess = Runtime.getRuntime().exec(compileCmd);
            ExecuteMessage executeMessage = ProcessUtils.runProcessAndGetMessage(compileProcess, "编译");
            System.out.println(executeMessage);
        } catch (Exception e) {
            return getErrorResponse(e);
        }
        
        // 3 执行代码，得到输出结果
        List<ExecuteMessage> executeMessageList = new ArrayList<>();
        for(String inputArgs : inputList) {
            StopWatch stopWatch = new StopWatch();
            //这里的 %s 就是参数
//            String runCmd = String.format("java -Xmx256m -Dfile.encoding=UTF-8 -cp %s Main %s", userCodeParentPath, inputArgs);
            String runCmd = String.format("java -Xmx256m -Dfile.encoding=UTF-8 -cp %s;%s -Djava.security.manager=%s Main %s", userCodeParentPath, SECURITY_MANAGER_PATH, SECURITY_MANAGER_CLASS_NAME, inputArgs);
            try {
                Process runProcess = Runtime.getRuntime().exec(runCmd);
                //超时控制
                new Thread(() ->{
                    try {
                        Thread.sleep(TIME_OUT);
                        System.out.println("超时啦，中断");
                        runProcess.destroy();
                    } catch (InterruptedException e) {
                        throw new RuntimeException(e);
                    }
                }).start();
                ExecuteMessage executeMessage = ProcessUtils.runProcessAndGetMessage(runProcess, "运行");
//              ExecuteMessage executeMessage = ProcessUtils.runInteractProcessAndGetMessage(runProcess, inputArgs);
                executeMessageList.add(executeMessage);
                System.out.println(executeMessage);
            } catch (IOException e) {
                return getErrorResponse(e);
            }
        }
        
        // 4 收集整理输出
        ExecuteCodeResponse executeCodeResponse = new ExecuteCodeResponse();
        List<String> outputList = new ArrayList<>();
        //取用时最大值，便于判断是否超时
        long maxTime = 0;
        for (ExecuteMessage executeMessage : executeMessageList) {
            String errorMessage = executeMessage.getErrorMessage();
            if(StrUtil.isNotBlank(errorMessage)){
                executeCodeResponse.setMessage(errorMessage);
                //用户提交的代码执行中存在错误
                executeCodeResponse.setStatus(3);
                break;
            }
            outputList.add(executeMessage.getMessage());
            Long time = executeMessage.getTime();
            if (time != null) {
                maxTime = Math.max(time, maxTime);
            }
        }
        //正常运行完成，状态设置为1
        if(outputList.size() == executeMessageList.size()) {
            executeCodeResponse.setStatus(1);
        }
        executeCodeResponse.setOutputList(outputList);
        JudgeInfo judgeInfo = new JudgeInfo();
        judgeInfo.setTime(maxTime);
        //todo 这里获取内存需要借助第三方库调用，非常麻烦
//        judgeInfo.setMemory();
        executeCodeResponse.setJudgeInfo(judgeInfo);
        
        // 5 文件清理
        if(userCodeFile.getParentFile() != null) {
            boolean del = FileUtil.del(userCodeParentPath);
            System.out.println("删除" + (del ? "成功" : "失败"));
        }
        
        return executeCodeResponse;
    }


    /**
     * 获取错误响应,封装一个错误处理方法，当程序抛出异常时，直接返回错误响应
     * @param e
     * @return
     */
    private ExecuteCodeResponse getErrorResponse(Throwable e){
        ExecuteCodeResponse executeCodeResponse = new ExecuteCodeResponse();
        executeCodeResponse.setOutputList(new ArrayList<>());
        executeCodeResponse.setMessage(e.getMessage());
        //表示代码沙箱错误
        executeCodeResponse.setStatus(2);
        executeCodeResponse.setJudgeInfo(new JudgeInfo());
        return executeCodeResponse;
        
    }
}
